Microsoft locked itself out of its own data centre. It wasn't enough.
Europe keeps demanding a cloud that American law cannot reach. It had one, and it let it die.
Deutsche Telekom held the keys, the servers sat in Germany, and Microsoft's own staff could not get in. From 2016 this was exactly what every sovereignty debate since has demanded. It stopped taking new customers two years later.
It did cost more. That is not what killed it. Customers wanted the range of services and the connections the global cloud offered. The German version did not have them.
The real premium was never just the money. It was capability.
That gap has not closed. European providers hold about 15 percent of their own market, unchanged for four years. The American big three hold most of the rest.
Europe is now writing the legal definition of a sovereign cloud around that. On June 3rd the Commission proposed the Cloud and AI Development Act (CADA), sorting cloud services into four levels. The top level shuts out foreign providers, and is meant for about one percent of public services.
The floor everyone must clear asks only that the data sits in Europe. Analysts say the American giants can already meet it. European providers agree, and warn it invites more sovereignty washing.
In June I wrote that rules only matter if the buying follows them. These rules match the buying that already happens.
Gaia-X, the 2020 plan for a European cloud, wrote rules and issued certificates and never built a data centre. The CEO of Nextcloud, a German alternative to Microsoft 365, called it "a paper monster that will exist but will not have any impact in the market". Scaleway, a French provider and a founding member, walked out saying the project was "reinforcing the status quo".
A four-level badge worries me for a reason beyond where the bar sits. A certificate turns a hundred decisions into one. You buy the floor, and nobody asks again whether your customer records, your tax data and your test environment belong in the same place.
That question is the entire job. Which data can sit under foreign law and which cannot. Where you need raw performance badly enough to accept a dependency. Where lock-in is a risk you have named, priced and chosen to carry, and where you never noticed taking it on. Those answers change layer by layer. No badge produces them for you.
Renting American infrastructure is defensible. I do it for plenty of workloads. What is not defensible is not knowing you made the choice.
Pick the system you would least like to explain to a parliamentary committee or your own board. Without looking it up, can you say whose law reaches it and what moving it would cost? A certificate will not tell you.
If you are working through that map right now, I would rather hear it than guess. Where does it get stuck?